{
  "type": "bundle",
  "id": "bundle--54611c58-2d48-59e2-8d50-5d37ca274a61",
  "objects": [
    {
      "type": "marking-definition",
      "spec_version": "2.1",
      "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
      "created": "2017-01-20T00:00:00.000Z",
      "definition_type": "tlp",
      "name": "TLP:WHITE",
      "definition": {
        "tlp": "white"
      }
    },
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-07T00:00:00.000Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "name": "skopnix",
      "identity_class": "organization",
      "description": "skopnix — open threat intelligence. Aggregated and published, not authored: cite the external_references, not us.",
      "contact_information": "https://skopnix.com"
    },
    {
      "type": "intrusion-set",
      "spec_version": "2.1",
      "created": "2026-09-07T00:00:00.000Z",
      "modified": "2026-09-15T11:55:05.370Z",
      "created_by_ref": "identity--c1b401e5-a927-598d-859c-fc757d058154",
      "object_marking_refs": [
        "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
      ],
      "id": "intrusion-set--b3eaa02d-f89d-5293-b30b-5994fc234376",
      "name": "NARWHAL SPIDER",
      "aliases": [
        "NARWHAL SPIDER",
        "GOLD ESSEX",
        "TA544",
        "Storm-0302"
      ],
      "description": "NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.",
      "external_references": [
        {
          "source_name": "skopnix",
          "external_id": "narwhal-spider",
          "url": "https://skopnix.com/actors/narwhal-spider"
        },
        {
          "source_name": "go.crowdstrike.com",
          "url": "https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf"
        },
        {
          "source_name": "secureworks.com",
          "url": "http://www.secureworks.com/research/threat-profiles/gold-essex"
        },
        {
          "source_name": "proofpoint.com",
          "url": "https://www.proofpoint.com/us/threat-insight/post/brushaloader-still-sweeping-victims-one-year-later"
        },
        {
          "source_name": "proofpoint.com",
          "url": "https://www.proofpoint.com/us/threat-insight/post/holiday-lull-not-so-much"
        },
        {
          "source_name": "proofpoint.com",
          "url": "https://www.proofpoint.com/us/threat-insight/post/urlzone-top-malware-japan-while-emotet-and-line-phishing-round-out-landscape-0"
        },
        {
          "source_name": "proofpoint.com",
          "url": "https://www.proofpoint.com/us/threat-insight/post/threat-actor-profile-ta544-targets-geographies-italy-japan-range-malware"
        },
        {
          "source_name": "proofpoint.com",
          "url": "https://www.proofpoint.com/us/blog/threat-insight/q4-2020-threat-report-quarterly-analysis-cybersecurity-trends-tactics-and-themes"
        }
      ]
    }
  ]
}